PT-2026-31416 · Zammad · Zammad

CVE-2026-34719

·

Published

2026-04-08

·

Updated

2026-04-09

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:L/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1 and prior to 6.5.4
Description Zammad, a web-based open-source helpdesk/customer support system, had insufficient validation in its webhook model for loopback or link-local addresses. Only the URL scheme (HTTP/HTTPS) and hostname were checked, potentially allowing the retrieval of confidential metadata from cloud or hosting providers. The validation has been extended and is now applied during webhook configuration and job triggering.
Recommendations Update to Zammad version 7.0.1 or later. Update to Zammad version 6.5.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34719
GHSA-2VGC-VFH2-RW75

Affected Products

Zammad